PT-2024-25792 · Unknown · Ordat Foss-Online

Christian Stehle

+1

·

Published

2024-09-12

·

Updated

2024-09-18

·

CVE-2024-34334

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions ORDAT FOSS-Online versions prior to 2.24.01
Description The issue is related to a SQL injection vulnerability in the forgot password function.
Recommendations For versions prior to 2.24.01, update to version 2.24.01 or later to resolve the issue. As a temporary workaround, consider restricting access to the forgot password function until a patch is available.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-34334

Affected Products

Ordat Foss-Online